RANSOMWARE VICTIMBUSINESS SERVICES

Grupolider | Grupo Actual

deadlock📍 AO (AO)📅 June 15, 2026
8
same group

Attack Intelligence

Grupolider | Grupo Actual was compromised in a ransomware attack attributed to deadlock in June 2026. The organization, operating in the Business Services sector in AO, was added to the group's data leak site as part of an extortion campaign.

deadlock operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

The leaked files will be available for download on May 10, 2026. Grupolider is a prominent Angolan conglomerate that has been operating in the national market since 1999. Headquartered in Catete, Luanda, the group initially started as a freight forwarding company and has since diversified into a wide range of sectors including agriculture, construction, and furniture. Grupo Actual is a human resources and recruitment agency in Portugal that provides temporary work solutions, permanent recruitment, and selection services.Following a rebranding in late 2025, the company formerly known as Leader now operates under the Actual brand. https://grupolider-ao.com/ https://grupoactual.pt/

Additional Details

Other Victims — deadlock (8)

Quick Facts

CountryAO (AO)
SectorBusiness Services
Attack DateJun 15, 2026
Intel Sourceransomlook

Threat Group

deadlock
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.